← Back

CVE-2020-7453

nvd nist
Published: Apr 29, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.0
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Exploitability: 0.8 / Impact: 5.2
Source: NVD

Description

In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes with a subsequent jail_get system call allowing a malicious jail superuser with permission to create nested jails to read kernel memory.

Affected (10)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 11.3
Version 11.3 p1
Version 11.3 p2
Version 11.3 p3
Version 11.3 p4
Version 11.3 p5
Version 11.3 p6
Version 12.1
Version 12.1 p1
Version 12.1 p2

References (2)

Source: secteam@freebsd.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.